Title: SD-Wan Local DNS server on HQ Router [Print this page] Author: Matt1tay2@gmail Time: 2026-9-28 02:42 Title: SD-Wan Local DNS server on HQ Router You can point the DHCP DNS server at your remote nodes to the HQ router's IP address across the SD-WAN tunnel, but it comes with a major catch.
Here is exactly how the network will behave if you do this:
Node-to-HQ Resolution (Works): The clients at the remote nodes will successfully resolve hostnames for devices located at HQ.
Node Local Resolution (Fails): The clients at the remote nodes will lose the ability to resolve hostnames for devices at their own site.
Node-to-Node Resolution (Fails): Clients at Site A will not be able to resolve hostnames for devices at Site B.
This happens because the HQ router only tracks the DHCP leases it hands out on its own local networks. If a PC at a branch site asks the HQ router for the IP address of a camera sitting on the same branch network, the HQ router won't know the answer. It will forward that request out to Google, and it will fail.
To get full multi-site resolution across an SD-WAN without breaking local resolution, standard router DNS forwarders are usually insufficient. You would need to set up a dedicated DNS server (like Windows Server DNS or a small Linux VM running dnsmasq) at HQ and configure it with conditional forwarders—explicitly telling that central server to query the Site A gateway for Site A hostnames, and the Site B gateway for Site B hostnames.
If you are only trying to access a handful of specific devices across the SD-WAN (like remote NVRs or access control panels), it is much easier to just assign those devices static IP addresses or add a few manual static DNS entries into the local gateway at each site.
Welcome to Ruijie Community (https://community.ruijie.com/)